Related Threat Clusters
-
Destructive Lotus Wiper Targets Venezuelan Energy Sector Amid Geopolitical Tensions
In late 2025 and early 2026, a new data-wiping malware known as Lotus Wiper was identified targeting the energy and utilities sector in Venezuela. The malware was uploaded to a public platform in mid-December 2025 and…
8 articles · Updated April 21, 2026 -
Fire Ant Threat Actor Targets Trusted Infrastructure in 2026
The China-nexus threat actor known as Fire Ant has evolved its tactics in 2026, transitioning from targeting VMware hypervisors to compromising trusted infrastructure, including Cisco routers, TACACS authentication…
22 articles · Updated August 30, 2026 -
MikroTik RouterOS Vulnerabilities Under Active Exploitation
CERT Polska has identified six critical vulnerabilities in MikroTik RouterOS, with two of them forming an attack chain named MikroTrick. This chain allows attackers to gain full administrative control of devices via SSH…
16 articles · Updated September 6, 2026 -
Iranian APT Groups Target Israeli Organizations with Modular C2 Frameworks
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
10 articles · Updated July 6, 2026 -
Storm-0501 Cybercrime Group Targets Azure with Ransomware Tactics
Storm-0501, a financially motivated cybercrime group, has been active since 2021 and is known for conducting ransomware operations using various Ransomware-as-a-Service (RaaS) variants. They have recently expanded their…
2 articles · Updated August 17, 2026 -
Critical Auth Bypass and RCE Vulnerability in Apache Superset
Apache Superset has been found to have a critical security vulnerability, CVE-2023-27524, that allows for authentication bypass and remote code execution (RCE). This flaw arises from a default insecure configuration,…
2 articles · Updated September 10, 2026 -
ExfilSquad Targets Wesco in Major Data Theft Incident
On August 11, 2026, Wesco, a global supply chain company, confirmed a cybersecurity incident involving data theft by the group ExfilSquad. The group claimed to have stolen 2.6 million records from Wesco's cloud CRM…
13 articles · Updated August 12, 2026 -
Storm-2949 Cyberattack Targets Microsoft 365 and Azure Data
Microsoft has reported a significant cyberattack by the threat actor Storm-2949, which exploited Microsoft Entra ID accounts to conduct a large-scale data theft from Microsoft 365 and Azure environments. The attack…
6 articles · Updated May 19, 2026 -
Critical CosmosEscape Vulnerability Exposes Azure Cosmos DB to Potential Attacks
Wiz Research disclosed a critical vulnerability named CosmosEscape in Azure Cosmos DB, allowing attackers to potentially compromise every database in the service, including Microsoft's internal systems like Entra ID,…
6 articles · Updated July 30, 2026 -
OAuth Client ID Spoofing Threatens Microsoft Entra Security
Cybercriminals are increasingly using OAuth client ID spoofing to conduct account enumeration against Microsoft Entra, the identity management service. This method allows attackers to infer username and password…
12 articles · Updated July 13, 2026
Recent Intelligence Reports
- CVE-2020 — Sploitus · September 10, 2026
- Weekly ALL-SOURCE Cyber Warfare Intelligence Brief September 8, 2026 — Krypt3Ia.Wordpress · September 8, 2026
- Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update ... — Cert.Pl · September 6, 2026
- Operation ASTERIX Uses Vishing and Fake Crypto Wallet Apps to Steal Seed Phrases — Gbhackers · August 18, 2026
- Storm-0501 — attack.mitre.org · August 18, 2026
- Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline — Rapid7 · August 17, 2026
- Wesco Cloud CRM Data Breach: ExfilSquad Data Theft and Supply Chain Risks Analyzed — Rescana · August 12, 2026
- Akira Hits Safe Mode: Ransomware Rebooting Around EDR — Huntress · August 12, 2026